A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users.
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:6122 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-50311 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2319379 | issue tracking |